poc/examples/nmap-{streaming,callback}.pow: minor cleanup

* Update comments.
* Add Content-Type: text/xml header (nmap-streaming.pow) only.
* Wrap the Nmap output in XML comment delimiters, *after* the XML header.
* Write to /response/body (preferred) instead of /response/stream (legacy).
* Use suffix .xml for temp files.
* Move possibly noise-generating calls outside of the block
  that is sent to the /request/body.
This commit is contained in:
pancho horrillo
2019-10-24 17:05:54 +02:00
parent b0c16ca684
commit 2fc18b76e3
2 changed files with 35 additions and 29 deletions
+18 -14
View File
@@ -17,8 +17,10 @@
#
#
# Streams nmap execution. When processes finishes print the value ##########"
# as separator and then print the Nmap XML report
# Streams nmap execution.
#
# The output from Nmap is wrapped in XML comment delimiters
# and then follows the Nmap XML report proper
#
# Call example:
@@ -27,16 +29,19 @@
#
kapow route add -X POST /nmap-stream - <<-'EOF'
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
tmpfile="$(mktemp --suffix=.xml)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
kapow set /response/headers/Content-Type text/xml
{
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
tmpfile="$(mktemp --suffix=.nmap)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
echo '<?xml version="1.0" encoding="UTF-8"?>'
echo '<!--'
nmap \
-Pn \
@@ -45,8 +50,7 @@ kapow route add -X POST /nmap-stream - <<-'EOF'
-oX "$tmpfile" \
"$IP"
echo '-->'
tail --lines=+2 "$tmpfile"
cat "$tmpfile"
} | kapow set /response/stream
} | kapow set /response/body
EOF